Threat Advisory

Semaphore UI CSRF Vulnerability on Password Change Endpoint

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities have been identified in github., affecting version range not explicitly stated in the article. The overall risk and impact of these vulnerabilities are significant, as they can lead to unauthorized access and privilege escalation.

CVE-2026-73292 (CVSS 7.5 — High Severity): A CSRF vulnerability exists on the password change endpoint due to the absence of a CSRF token or password confirmation. An attacker with malicious intent can exploit this vulnerability to perform unauthorized actions.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities have been identified in github., affecting version range not explicitly stated in the article. The overall risk and impact of these vulnerabilities are significant, as they can lead to unauthorized access and privilege escalation.

CVE-2026-73292 (CVSS 7.5 — High Severity): A CSRF vulnerability exists on the password change endpoint due to the absence of a CSRF token or password confirmation. An attacker with malicious intent can exploit this vulnerability to perform unauthorized actions.[emaillocker id="1283"]

CVE-2026-73293: A privilege escalation vulnerability exists via custom-role slug collision, allowing an attacker to gain manager-to-owner privileges.

RECOMMENDATION:

We recommend you to update Semaphore UI to version 0.0.0-20260707190631-c59c3dc9035b.

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu